Oracle iPlanet Web Server 7.0.x < 7.0.9 Multiple Vulnerabilities

This script is Copyright (C) 2010-2015 Tenable Network Security, Inc.


Synopsis :

The remote web server is affected by multiple vulnerabilities.

Description :

According to its self-reported version, the Oracle iPlanet Web Server
(formerly known as Sun Java System Web Server) running on the remote
host is 7.0.x prior to 7.0.9. It is, therefore, affected by multiple
vulnerabilities :

- An unspecified file disclosure vulnerability exists in
the WebDAV component. (CVE-2010-3512)

- An HTTP response splitting vulnerability exists in the
web container component due to a failure to sanitize
HTTP response headers of CR / LF characters.
(CVE-2010-3514)

- A cross-site request forgery vulnerability exists in
the management console that can allow an attacker to
stop an arbitrary server instance. (CVE-2010-3544)

- An unspecified flaw exists in the administration
component that allows a remote attacker to impact
confidentiality and integrity via unknown vectors.
(CVE-2010-3545)

See also :

http://jvn.jp/en/jp/JVN50133036/index.html
http://www.nessus.org/u?1ad07b4e

Solution :

Upgrade to Oracle iPlanet Web Server 7.0.9 or later.

Risk factor :

Medium / CVSS Base Score : 5.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N)
CVSS Temporal Score : 4.5
(CVSS2#E:POC/RL:OF/RC:C)
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 51138 ()

Bugtraq ID: 43977
43984
44004
44034

CVE ID: CVE-2010-3512
CVE-2010-3514
CVE-2010-3544
CVE-2010-3545